Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization uses Microsoft Purview Information Protection to classify and protect sensitive data. The compliance team wants to automatically apply a 'Highly Confidential' sensitivity label to emails that contain credit card numbers. Which solution should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview auto-labeling policy

The correct option is A, Microsoft Purview auto-labeling policy, because auto-labeling policies are the native Purview Information Protection mechanism that scans content for sensitive information types (such as credit card numbers) and automatically applies a specified sensitivity label like 'Highly Confidential' to emails and files. This directly matches the requirement to classify and protect data at the label level, since sensitivity labels can also enforce encryption and other protection settings. Option B, Safe Attachments, is a Defender for Office 365 threat-detection feature that sandboxes attachments and does not apply sensitivity labels. Option C, a DLP policy, can detect credit card numbers and block or warn on sharing, but it enforces DLP rules rather than automatically applying a sensitivity label. Option D, Microsoft Endpoint DLP, extends DLP controls to endpoint devices and likewise does not apply sensitivity labels to email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Purview auto-labeling policy

    Why this is correct

    Microsoft Purview auto-labeling is the correct mechanism because it can evaluate email content and context (e.g., sensitive info types like credit card numbers, or trainable classifiers) and automatically assign sensitivity labels to messages. Policies run in simulation mode or enforce automatically, and label actions like encryption can then be applied based on the label. This directly addresses the requirement to apply an information protection label to emails.

  • ✗

    Microsoft Defender for Office 365 Safe Attachments policy

    Why it's wrong here

    Microsoft Defender for Office 365 Safe Attachments is incorrect because it focuses on malware protection, not labeling. Its policy scans email attachments in a detonation chamber to detect malicious files and can block or quarantine threats, but it has no capability to assess content for sensitivity or assign a Purview sensitivity label. Labeling is a data classification function, not a threat-detection function.

  • ✗

    Microsoft 365 Data Loss Prevention (DLP) policy

    Why it's wrong here

    Microsoft 365 DLP is incorrect because DLP policies perform actions such as blocking, restricting, or encrypting data when sensitive content matches a rule — they do not apply sensitivity labels. While DLP can be configured to detect emails that already have a specific label and then enforce protection, it cannot itself assign a label to an email as a primary output. Label application requires auto-labeling or manual labeling, not DLP.

  • ✗

    Microsoft Endpoint DLP

    Why it's wrong here

    Microsoft Endpoint DLP is incorrect because it is designed for data protection on Windows and macOS endpoints, not email. It monitors file activity, removable storage, and clipboard operations on devices, and can enforce DLP rules on untrusted apps and cloud egress, but it does not scan or label email messages sent through Exchange Online. The question specifically requires email labeling, which is outside Endpoint DLP's scope.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.